diff mbox series

[scarthgap,v2,3/8] libxml2: mark CVE-2026-86139 fixed

Message ID 20261005092346.1670265-3-hthakar@cisco.com
State New
Headers show
Series [scarthgap,v2,1/8] libxml2: Fix CVE-2026-86137 | expand

Commit Message

From: Hetvi Thakar <hthakar@cisco.com>

The fix for CVE-2026-86139 adds a zero-length guard in
xmlURIEscapeStr, as shown in the upstream commit [1].

The libxml2 2.12.10 source already contains the equivalent guard [3],
so no additional patch is required. Mark the CVE as fixed in the
recipe.

[1] https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-86139
[3] https://github.com/GNOME/libxml2/blob/v2.12.10/uri.c#L1689-L1700

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
Changes in v2
- added xmlURIEscapeStr function url
---
 meta/recipes-core/libxml/libxml2_2.12.10.bb | 5 +++++
 1 file changed, 5 insertions(+)
diff mbox series

Patch

diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb
index 28ae601118..53e8660366 100644
--- a/meta/recipes-core/libxml/libxml2_2.12.10.bb
+++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb
@@ -46,6 +46,11 @@  CVE_STATUS[CVE-2023-45322] = "disputed: issue requires memory allocation to fail
 # https://gitlab.gnome.org/GNOME/libxml2/-/issues/958
 CVE_STATUS[CVE-2025-8732] = "disputed: the code maintainer explains, that the issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. The issue triggers a crash if an invalid file is provided.  https://gitlab.gnome.org/GNOME/libxml2/-/issues/958"
 
+# The Scarthgap 2.12.10 source already contains the equivalent zero-length
+# guard required for the xmlURIEscapeStr integer-overflow issue.
+# https://github.com/GNOME/libxml2/blob/v2.12.10/uri.c#L1689-L1700
+CVE_STATUS[CVE-2026-86139] = "fixed-version: xmlURIEscapeStr returns NULL when xmlStrlen returns zero"
+
 BINCONFIG = "${bindir}/xml2-config"
 
 PACKAGECONFIG ??= "python \